Description
WordPress Plugin Wrapper Link Elementor contains malicous code. Exploiting this issue may allow an attacker to create a new administrative user account, thus compromising the affected application, and possibly the webserver or computer. WordPress Plugin Wrapper Link Elementor versions 1.0.2 - 1.0.3 are affected.
Remediation
Update to plugin version 1.0.5 or latest
References
Related Vulnerabilities
Drupal Permissions, Privileges, and Access Controls Vulnerability (CVE-2014-9015)
ATutor Unrestricted Upload of File with Dangerous Type Vulnerability (CVE-2019-12170)
WordPress Plugin Smash Balloon Social Post Feed Unspecified Vulnerability (2.4.2)
WordPress Plugin PowerPack Lite for Beaver Builder Cross-Site Scripting (1.2.9.2)